<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ADF CSRF- Error in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/adf-csrf-error/m-p/41892#M17572</link>
    <description>&lt;P&gt;I am using ADF with APS.&lt;/P&gt;&lt;P&gt;During Login I am getting CSRF Error.&lt;/P&gt;&lt;P&gt;ADF is using Rest API to communicate with APS and it is using Public API.&lt;/P&gt;&lt;P&gt;As Per this&amp;nbsp;&lt;A href="https://docs.alfresco.com/process-services1.9/topics/cross_site_request_forgery.html" target="_blank" rel="noopener nofollow noreferrer"&gt;https://docs.alfresco.com/process-services1.9/topics/cross_site_request_forgery.html&lt;/A&gt;&amp;nbsp;is is saying that for Public API CSRF Protection is not required.&lt;/P&gt;&lt;P&gt;One solution is we can disable in APS but it may create some security issue.&lt;/P&gt;&lt;P&gt;Can any one clarify on this?&lt;/P&gt;&lt;P&gt;Login component having disableCsrf but not working.&lt;/P&gt;&lt;P&gt;I am using this login api as we have custom login page.&amp;nbsp;&lt;A href="https://www.alfresco.com/abn/adf/docs/core/services/authentication.service/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.alfresco.com/abn/adf/docs/core/services/authentication.service/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/16045"&gt;@afaust&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/5487"&gt;@angelborroy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 01 Dec 2020 13:52:32 GMT</pubDate>
    <dc:creator>sp2</dc:creator>
    <dc:date>2020-12-01T13:52:32Z</dc:date>
    <item>
      <title>ADF CSRF- Error</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/adf-csrf-error/m-p/41892#M17572</link>
      <description>&lt;P&gt;I am using ADF with APS.&lt;/P&gt;&lt;P&gt;During Login I am getting CSRF Error.&lt;/P&gt;&lt;P&gt;ADF is using Rest API to communicate with APS and it is using Public API.&lt;/P&gt;&lt;P&gt;As Per this&amp;nbsp;&lt;A href="https://docs.alfresco.com/process-services1.9/topics/cross_site_request_forgery.html" target="_blank" rel="noopener nofollow noreferrer"&gt;https://docs.alfresco.com/process-services1.9/topics/cross_site_request_forgery.html&lt;/A&gt;&amp;nbsp;is is saying that for Public API CSRF Protection is not required.&lt;/P&gt;&lt;P&gt;One solution is we can disable in APS but it may create some security issue.&lt;/P&gt;&lt;P&gt;Can any one clarify on this?&lt;/P&gt;&lt;P&gt;Login component having disableCsrf but not working.&lt;/P&gt;&lt;P&gt;I am using this login api as we have custom login page.&amp;nbsp;&lt;A href="https://www.alfresco.com/abn/adf/docs/core/services/authentication.service/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.alfresco.com/abn/adf/docs/core/services/authentication.service/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/16045"&gt;@afaust&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;A href="https://migration33.stage.lithium.com/t5/user/viewprofilepage/user-id/5487"&gt;@angelborroy&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 13:52:32 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/adf-csrf-error/m-p/41892#M17572</guid>
      <dc:creator>sp2</dc:creator>
      <dc:date>2020-12-01T13:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: ADF CSRF- Error</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/adf-csrf-error/m-p/41893#M17573</link>
      <description>&lt;P&gt;The APS CSRF guard can safely be disabled. It does not add any kind of security that is more than just the placebo effect of ticking the "CSRF"-box. Somewhere on this platform, an Alfresco engineer of ADF has unmistakingly stated that CSRF is not required for the ADF app and can be disabled. I have had to disable CSRF at three customers now because of the bugs / side effects it introduced.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Dec 2020 14:40:07 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/adf-csrf-error/m-p/41893#M17573</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2020-12-01T14:40:07Z</dc:date>
    </item>
  </channel>
</rss>

